Evidence map›Paper›PMID 42190643›Full record

ArticleJMIR formative research2026

Differences in Safety Risks Across Languages in Health-Relevant Queries: Vulnerability Analysis of Large Language Model Responses.

Saubhagya Joshi, Monjil A Mehta, Melissa Mendoza, Yonaira M Rivera, Vivek K Singh

Abstract read
In one paragraph

Article in JMIR formative research, 2026. The graph could read no effect estimate from its abstract, so it casts no vote on the map. Not yet cited in PubMed.

0numbers the graph read from it
0cells of the map it votes in
0citing papers in PubMed
–field-weighted citation impact
1 · What the graph read from it

What it found

Each row is one number read from the abstract, on the scale the paper reported it, with its interval. Left of the dashed line favours the treatment, right favours the comparator. Under each row is the sentence it came from. New to these charts? A ten-minute tutorial.

The abstract states no effect estimate the extractor could read, or names no intervention and outcome on the map, so this paper lights no cell and moves no belief. It is still indexed, cited and linked below.

2 · The registry

The trial behind it

Trials whose registry record cites this paper, or whose number appears in the abstract. A trial that started after this paper was published is citing it as background, not reporting it.

Neither the registry nor the abstract names a trial number. If this is a trial report, that itself is worth knowing.

3 · Its place in the literature

Who cites it

0 citing papers in PubMed.

No citing paper in PubMed yet.

4 · The record

Corrections and comments

PubMed lists nothing against this paper. Absence here is not a guarantee, only a check that was made.

5 · Who and what money

Authors and funding

5 authors.

Saubhagya JoshiRutgers, The State University of New Jersey, 4 Huntington Street, New Brunswick, NJ, 08901, United States, 1 848-932-7500.ORCID 0009-0000-8067-6227
Monjil A MehtaRutgers, The State University of New Jersey, 4 Huntington Street, New Brunswick, NJ, 08901, United States, 1 848-932-7500.ORCID 0009-0008-8053-5983
Melissa MendozaRutgers, The State University of New Jersey, 4 Huntington Street, New Brunswick, NJ, 08901, United States, 1 848-932-7500.ORCID 0009-0007-7635-5202
Yonaira M RiveraRutgers, The State University of New Jersey, 4 Huntington Street, New Brunswick, NJ, 08901, United States, 1 848-932-7500.ORCID 0000-0002-5041-5250
Vivek K SinghRutgers, The State University of New Jersey, 4 Huntington Street, New Brunswick, NJ, 08901, United States, 1 848-932-7500.ORCID 0000-0002-8194-2336

Funding

No grant is acknowledged in the PubMed record.

6 · The paper itself

Abstract

Background: Large language models (LLMs) such as ChatGPT are increasingly used to support health-related queries and decision-making. However, these models can be "jailbroken" through adversarial prompts that bypass safety filters and elicit harmful or medically inappropriate responses. In health care contexts, such vulnerabilities pose serious risks. Understanding how jailbreak susceptibility varies across languages is essential for developing robust safeguards and promoting equitable access to safe health information. This paper may contain examples that may be deemed harmful in terms of violence, self-harm, and drug abuse. Objective: This study aims to systematically compare and contrast the vulnerability of a health LLM for jailbreaking across 3 languages: English, Spanish, and Hindi (transliterated using the Latin alphabet), based on emoji and permutation cipher attacks. Methods: We analyzed 1000 input prompts per language, drawn from the BeaverTails dataset, across 3 harm categories: self-harm, violence, and drug abuse. Each prompt was modified using emoji and permutation cipher techniques, resulting in 6000 input-output pairs. Model responses were evaluated by human coders to determine the success rate of jailbreak attempts across languages and cipher types. Results: Hindi prompts showed the highest vulnerability, with 787 successful jailbreaks using emoji ciphers and 873 using permutation ciphers. Spanish and English followed, with lower success rates across both cipher types. Differences in jailbreak success across languages and cipher strategies were statistically significant. Additionally, attacks targeting violence-related prompts were more successful overall than those targeting drug-related or self-harm content, indicating variation in vulnerability by harm type. Conclusions: The findings of this formative study reveal that LLM safety performance varies substantially across languages and harm categories, raising concerns about equitable protection in multilingual health communication. Disparities in access to harmful content may contribute to downstream health risks. Strengthening multilingual content moderation and developing language-aware safety mechanisms are critical steps toward creating safer and more inclusive health AI systems.

Indexed as

LanguageLarge Language ModelsHumansAI safetyartificial intelligenceChatGPTemoji cipherEnglishharm categoriesHindijailbreak attackslanguage modelslarge language modelsmultilingual vulnerabilitiespermutation cipherSpanish

Identifiers

PMID42190643
PMCPMC13211943

What OpenQuestion holds

Textmetadata
LicenceCC BY
Read underepoch 390

Registered trials

None linked

Read under generation 80e0d062 · epoch 390. Bibliography from PubMed, PubMed Central and OpenAlex; grants from NIH RePORTER; trial links from ClinicalTrials.gov; estimates, votes and beliefs from the OpenQuestion graph.